Unauthorized Access Vulnerability in Splunk Enterprise and Secure Gateway by Splunk
CVE-2026-76327

6.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76327?

In certain versions of Splunk Enterprise and Splunk Secure Gateway, an unauthenticated user can exploit improper input validation to deceive an admin user into executing crafted URLs. This can lead to the execution of arbitrary Search Processing Language (SPL) commands under the privileges of the affected user, allowing an attacker to expose sensitive data. The security flaw stems from inadequate handling of caller-supplied values in dashboard searches, making it essential for users to be cautious of phishing attempts that aim to exploit this vulnerability.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.